It's an utter racket.
Those of us with technical inclination need to be sure to point our family and friends with less technical inclinations to the Microsoft Stores and "Signature Edition" [1] PCs, Microsoft's latest marketing term for unbloated Windows installs out of the box. Some of our friends and families may feel they have a special relationship with an existing OEM, so give them the "Signature Edition" website and have them at least bug their OEM to ship them one.
[1] http://www.microsoftstore.com/store/msusa/en_US/cat/category...
You have no idea where that computer's been before you.
Here's the ArsTechnica guide for doing a clean install of Windows 8.1 – imagine walking the average home user through this process, even before you factor in discouragements such as the likelihood of tech support blaming any problem more subtle than catching fire on your reinstall:
http://arstechnica.com/gadgets/2015/02/save-yourself-from-yo...
This, in a nutshell, is a major source of Apple selling so many iOS devices – I regularly hear people say that it's easier to have a good, secure computing experience that way and they're not wrong.
http://www.howtogeek.com/174587/refreshing-your-pc-wont-help...
http://www.howtogeek.com/216751/bloatware-banished-windows-1...
Windows 8 and 10 also have a lovely feature called the Windows Platform Binary Table. This allows OEMs to write an application into the UEFI, and Windows will automatically deploy to memory and run it with admin privileges each time it boots. The intended use was for installing drivers and anti-theft agents, but of course it was immediately used to drop bloatware/malware. This vector works even on entirely fresh installs, and there is no mitigation except obtaining a clean, signed UEFI image.
https://www.techdirt.com/articles/20150812/11395231925/lenov...
http://www.howtogeek.com/226308/the-windows-platform-binary-...
Laptop manufacturers are also to blame because product bundling and bloatware are nothing new.
Microsoft on their part could make it so that Defender worked alongside McAfee but that might encourage users to buy McAfee even more, arguably (double the protection or not knowing they are already protected).
Further info here: https://news.ycombinator.com/item?id=9653111
Then there is Superfish...
Who knows what else they are going?
For one thing, last time I checked benchmarks they showed that Microsoft's anti-virus not only has worse detection results but also worse performance than some of the free alternatives.
I don't know about other antivirus software though.
Page 9 of the latest report: http://www.av-comparatives.org/summary-reports/
the glaring security holes opened by them month after month? The HN link you're posting a comment to is about the 5th bad exploit in third-party AV this year alone.
So far nothing seems to have been found in the MS built-in one.
Installing third-party AV means that you expose yourself to targeted attacks and, if this goes on like it currently does, to drive-by attacks too as by now malware authors must have gotten the hint that searching for vulnerabilities in those various AV products is a very worthwile effort.
In general, AV products provide a HUGE attack surface: They don't just need to support natively many more file formats than any other piece of software, they also have to harden their support against exploit code purposefully written to be malicious.
And compared to many exploitable user-space applications, these AV products normally run in kernel-space, so an attacker doesn't just gain remote code execution, they gain remote code execution with admin privileges.
EDIT: And there's anti-virus software that's messing with your system's root certificates so it can MitM all your HTTPS traffic to scan it:
http://www.securityweek.com/antivirus-software-has-negative-...
Slightly better snake oil is still snake oil.
Compiled and ran the code and immediately Bitdefender blocked the program and put up a "Keylogger detected" message.
Microsoft built in antivirus doesn't have this kind of behavioral detection protections.
Which is quite problematic because it was a false positive. You knew and wanted that program to log key presses.
That's the trouble with aggressive heuristics. Users are going to have a program that translates keyboard layouts by hooking the key presses. Or software that comes with some fancy input device.
Then the antivirus says it's a keylogger even though they know it isn't and the user is taught to expect good rather than bad things when they press "allow" against a something-is-wrong prompt.
From my experience there are very few legit reasons for intercepting keys, and the use cases you mentioned are better solved by implementing a device driver (which would be signed by MS).
Allowing non-elevated code to install system hooks also enlarges the attack surface, since now a malware piece can just infect your keyboard layout translator for getting keyboard access.
Me, I would like an Intent/Permission mechanism on Windows, where certain actions like keylogging or accessing other processes memory require explicit white-listing (like on Android/iOS). Currently some actions do require a certain privilege, but that privilege is granted per-user, not per-app, so it doesn't help that much.
That's assuming you have control over what third parties who write the software have done, and needing to go through the expensive bureaucratic process to get a driver signed is a major reason why they wouldn't do it that way if there was any alternative.
> Allowing non-elevated code to install system hooks also enlarges the attack surface, since now a malware piece can just infect your keyboard layout translator for getting keyboard access.
But now you're not talking about antivirus anymore. Installing things is expected to require privileges. There is a huge difference between a password prompt that says "authenticate if you want to install" and a red alert that says "malware detected and blocked, override may cause fire and mayhem."
Which is especially problematic when it's done by third party antivirus because it means the vendor of whatever software is being misdetected as malware probably didn't encounter that in their testing.
> Me, I would like an Intent/Permission mechanism on Windows, where certain actions like keylogging or accessing other processes memory require explicit white-listing (like on Android/iOS). Currently some actions do require a certain privilege, but that privilege is granted per-user, not per-app, so it doesn't help that much.
Fundamentally non-technical people don't understand what they're authorizing. It doesn't matter how granular the choices you provide are if the person in front of the button doesn't understand the implications.
You have to be able to trust the software you run, which implies trusting the people who made it. And people keep trying to solve that problem centrally when it isn't a central problem. Microsoft can't tell you if you can trust your brother, or the girl you met at the computer club. They can't tell you if you can trust Lenovo or Sourceforge. Microsoft certainly can't tell you if you can trust Microsoft. You have to decide, or decide who to trust to decide for you. And if you aren't going to decide for yourself then the person you trust to decide can't be Apple or Microsoft, it needs to be someone you personally actually trust, because central gatekeepers can't be trusted not to act against your interest when it's in theirs.
The alternative is that we don't see when a keylogger is being installed non-deliberately, and that would be worse IMO.
Plus, e.g. Comodo gives you a firewall. While I know that Windows has a perfectly good firewall, it doesn't come with a systray icon with a button labeled "protection from active network probes: active" or whatever.
Personally, I just have a router between me and the big bad internet and use Security Essentials plus Common Sense 2012.
If you're not technically inclined there are minefields everywhere.
Only to watch him say "I want to get vlc," type vlc into Google, skip over the VideoLAN - downloads link, and click some virus-infested link further down because the title of the link was "Get vlc."
This is why the scams work.
VideoLAN - Official page for VLC media player, the Open ...
The other results are all either directly or almost directly associated with VLC. I get no scam sites in the top 10 results. Have the search results improved? Is this the effect of search personalization? What gives?
People have reported this to various slackers for years but companies like Yahoo are loathe to turn down ad revenue and they still have millions of users.
To be fair, MS has recognized this and has been steadily improving detection rates. It has only recently been able to outdo Avast or AVG. Hopefully, this trend will continue. I imagine MS is under a lot of pressure to contain the Cryptolocker-type infections and the bad press of the past couple years is probably a motivator.
http://www.alphr.com/security/6745/best-free-antivirus-of-20...
Isn't this claim somewhat refuted by the very article you are posting against? There are other comments in this thread that explain why this doesn't make any sense eg pilif's above[1]
The comment you listed cites nothing, not sure why its so authoritative to you. All software has vulnerabilities, but where's the big attack on AV? What CVEs are we seeing in the wild, if any?